This application requires Javascript for optimal performance.

Rsyslog.Stack.Buffer.Overflow

Release Date

Jan 19, 2012

Severity

medium

Impact

Denial of Service: Remote attackers can crash vulnerable systems.

Description

This indicates an attack attempt against a Buffer Overflow vulnerability in rsyslog.

The vulnerability is caused by an error when the software handles specially crafted log message data. It allows a remote attacker to shutdown a remote log daemon.

Affected Products

rsyslog version 4.6.0 to 4.6.7 inclusive.
rsyslog version 5.2.0 to 5.8.4 inclusive.

Recommended Actions

Update to 4.6.8 or 5.8.5
http://www.rsyslog.com/rsyslog-4-6-8-v4-stable/
http://www.rsyslog.com/rsyslog-5-8-5-v5-stable/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-3200

Reference/s

http://www.rsyslog.com/potential-dos-with-malformed-tag/
https://bugzilla.redhat.com/show_bug.cgi?id=727644
http://www.securityfocus.com/bid/49413 (BugTraq)

Reference: VID-29191